Trade surveillance for MT4 / MT5 brokers: wash trading, spoofing and IB rebate abuse
A broker’s book generates the evidence of its own abuse every day: the deals file, the orders file, the deposits and the login log. Regulators in the UAE, Türkiye and the Gulf expect a licensed broker to look at that evidence systematically. Most brokers look at it when a bank, a liquidity provider or the regulator asks them to.
The four patterns that matter on a retail book
Wash trading: offsetting positions across accounts that share a beneficial owner, a device or a funding source, producing volume with no market risk. On a rebate-paying book it is profitable by construction, which is why it is common.
Spoofing and layering: bursts of pending orders cancelled within seconds, with fills on the opposite side. Visible only in the orders file, not the deals file.
IB rebate abuse: an introducing partner paid on volume whose clients generate matched or churned volume. The trade pattern and the rebate ledger have to be read together.
Funding anomalies: third-party deposits, structuring under the enhanced-due-diligence threshold, and dormant accounts reactivated with a new device, a bank change and an immediate withdrawal. These are AML typologies, but on a broker they show up in the same files.
The data you already have
Five end-of-day exports cover all of it: trades (ticket, login, time, symbol, side, volume, price, IB), orders (with placement, fill and cancellation times), transactions (deposits and withdrawals with channel and counterparty), clients (a KYC extract with beneficial-owner reference), and logins (device, IP, country). No integration project; a pilot starts on last quarter’s files the day they arrive.
What a rules engine adds
Deterministic rules with thresholds the firm can inspect and tune: matched-pair windows, order-to-fill ratios, cancellation latency, deposit bands. Every hit produces a case with the evidence rows that triggered it, the linked accounts, the funding source and, where the rule warrants it, a hold on a pending withdrawal. Explainable low-risk hits are closed with a written rationale so the morning queue is short.
A language model never decides what is suspicious. Where enabled, it rewrites the reasoning from the evidence table; every sentence must cite a record.
Regulatory context
In the UAE the CMA (formerly SCA), the DFSA and the FSRA all treat market-abuse surveillance as a licence condition for dealing activity; in Türkiye the SPK’s market-abuse communiqué and MASAK’s STR obligations apply to intermediaries; Gulf regulators (CMA Saudi Arabia, CBB, QFCRA) follow the same IOSCO principles. The obligation is proportionate, but relying on the liquidity provider’s alerts is not a surveillance programme.
Questions
Does this work with MT4 as well as MT5?
Yes. Both export the deals, orders and login files Marqib reads. The bridge or CRM usually holds the funding data.
How is IB rebate abuse detected?
Flagged volume is joined to the introducing partner reference on each trade; the case file states what the partner earned on that volume so the MLRO decides with the number in front of them.
Can thresholds be tuned per firm?
Yes. Every rule has explicit parameters (windows, ratios, bands) calibrated against the firm’s own history during the pilot.
Where does it run?
In the broker’s own cloud account, single-tenant. The vendor holds no client data.